Ransom Worm

Ransom:MSIL/WormLckr.SR!MTB information

Malware Removal

The Ransom:MSIL/WormLckr.SR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/WormLckr.SR!MTB virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine Ransom:MSIL/WormLckr.SR!MTB?


File Info:

crc32: 3F2C23CA
md5: f1315de16336b4f673d04469bd8678dc
name: F1315DE16336B4F673D04469BD8678DC.mlw
sha1: c00451ab11523151f561b66c0ce5401fe10c4838
sha256: d9447942df2ee749d1656d1b01f49e9a51bbdb369bca0bee7c9794e423b8485d
sha512: 8f60b9b635a042207a6b45264f5edb2597746ed6abe214f56621832f65858438810e8168987964ed917f7a9cc9237c4868c691a3ba7b50cd682fc83dd2631a21
ssdeep: 3072:oqxgbC1kfPSLcu7cIA5SvNbQGuI7hNVLokwLQLO3C/qY:U2vVQ21NV0zUiQq
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: WormLocker2.0.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: WormLocker2.0
ProductVersion: 1.0.0.0
FileDescription: WormLocker2.0
OriginalFilename: WormLocker2.0.exe

Ransom:MSIL/WormLckr.SR!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.EncoderNET.31372
CynetMalicious (score: 100)
ALYacGeneric.HidroClutter.A.2B823C87
CylanceUnsafe
Cybereasonmalicious.16336b
CyrenW32/MSIL_Ransom.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.AEP
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:Trojan-Ransom.MSIL.Encoder.gen
BitDefenderGeneric.HidroClutter.A.2B823C87
MicroWorld-eScanGeneric.HidroClutter.A.2B823C87
Ad-AwareGeneric.HidroClutter.A.2B823C87
BitDefenderThetaGen:NN.ZemsilF.34670.hm0@auZTpMg
McAfee-GW-EditionBehavesLike.Win32.Backdoor.cc
FireEyeGeneric.mg.f1315de16336b4f6
EmsisoftGeneric.HidroClutter.A.2B823C87 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1141655
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:MSIL/WormLckr.SR!MTB
ArcabitGeneric.HidroClutter.A.2B823C87
GDataGeneric.HidroClutter.A.2B823C87
AhnLab-V3Malware/Win32.RL_Generic.C4311185
McAfeeRDN/Ransom
MAXmalware (ai score=82)
MalwarebytesRansom.WormLocker
IkarusTrojan-Ransom.FileCrypter
FortinetMSIL/Filecoder.AEP!tr.ransom
AVGWin32:Trojan-gen

How to remove Ransom:MSIL/WormLckr.SR!MTB?

Ransom:MSIL/WormLckr.SR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment